Esc
Rogue Domain Controller - T1207
(ATT&CK® Technique)
Definition
Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be used to create a rogue Domain Controller (DC). DCShadow is a method of manipulating Active Directory (AD) data, including objects and schemas, by registering (or reusing an inactive registration) and simulating the behavior of a DC. Once registered, a rogue DC may be able to inject and replicate changes into AD infrastructure for any domain object, including credentials and keys.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.